1. Who we are
Rangka.co is operated by:
Operator: [REGISTERED LEGAL NAME]
Company registration number: [COMPANY REGISTRATION NUMBER]
Registered address: [REGISTERED ADDRESS]
Privacy and data requests: [LEGAL AND PRIVACY CONTACT EMAIL]
2. Scope and responsibilities
This policy applies to the Rangka.co website, platform, support interactions, and connected project workflows. For account, website, security, and commercial administration data, Rangka.co determines how and why personal data is handled.
For project information submitted to a company workspace, the Customer generally decides why that information is collected and who may use it. Rangka.co handles it to provide the service on the Customer’s instructions. Users should direct project-specific access or correction questions to their employer or workspace owner first.
3. Personal data we collect
- Account and company data: name, work email, account identifiers, company, role, project assignments, invitation and login information.
- Project and field data: project names, locations, schedules, tasks, progress, daily reports, approvals, comments, messages, photographs, files, voice notes, transcripts, and related metadata.
- Connected-channel data: Telegram identifiers, group or chat identifiers, sender details, message timestamps, and content submitted through a connected channel.
- Usage and technical data: device and browser information, IP address, timestamps, pages and features used, diagnostics, audit events, and security logs.
- Commercial data: selected plan, active-project allowance, subscription status, invoices, and limited payment-related information when billing is enabled. Full card details are handled by the payment provider, not stored by Rangka.co.
- Communications: support requests, feedback, survey responses, and other correspondence.
4. Where personal data comes from
We receive data directly from you; from your company, workspace owner, colleagues, or project participants; from connected services such as Telegram; from support conversations handled through Crisp; and automatically from your browser, device, and use of the platform. We may also receive billing and account status from service providers.
5. How and why we use personal data
We use personal data to:
- create and secure accounts and company workspaces;
- deliver project messaging, controls, reports, project schedule views, records, and exports;
- connect authorised communication channels and attribute submitted evidence;
- prepare AI-assisted drafts for human review;
- administer trials, subscriptions, active-project limits, and payments;
- provide support, communicate service changes, and respond to requests;
- detect misuse, protect users, preserve audit integrity, and troubleshoot;
- analyse and improve performance, reliability, accessibility, and product design; and
- comply with law, enforce agreements, and establish or defend legal claims.
Depending on the context, this processing is necessary to provide the requested service, carried out with consent, required by law, or reasonably necessary for security and legitimate business operations without overriding applicable rights.
6. AI-assisted processing
Rangka.co may send relevant project content to contracted AI service providers to transcribe, classify, summarise, extract project details, or prepare draft reports. AI output is not automatically approved. An authorised user must review it before it becomes an approved project record.
We limit AI processing to the information needed for the requested feature and apply contractual and technical controls appropriate to the service. Customers should avoid submitting unrelated sensitive personal data.
8. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal data, including access controls, tenant separation, encrypted transport, managed infrastructure, backups, logging, and restricted administrative access. No system is completely secure, so Customers must also manage memberships, passwords, connected channels, devices, and exports carefully.
9. Retention, recovery and deletion
We retain personal data while needed to operate the workspace, provide the service, maintain security and audit integrity, meet legal or contractual obligations, and resolve disputes. Simply not logging in does not by itself start deletion.
- After an unpaid trial expires, the workspace is read-only for 30 days before Customer data is scheduled for deletion.
- After a paid subscription ends, paid access continues through the billing period and is followed by a 90-day read-only recovery period before Customer data is scheduled for deletion.
- A payment failure may cause temporary read-only access while payment recovery is attempted; it is not classified as inactivity.
- Downgrading a plan or losing access to Portfolio Timeline does not by itself delete the underlying portfolio information.
Where supported, workspace administrators can export data during the recovery period and will be shown or sent the planned deletion date and reminders. A verified deletion request may begin a separate closure process.
Deletion remains subject to backup cycles, technical processing time, fraud prevention, legal holds, and required legal or contractual retention. Approved reports, audit history, and supporting evidence may need to be retained, access-restricted, or de-identified. Residual encrypted backup copies are isolated from ordinary use and expire according to backup schedules.
10. Your rights and choices
Subject to applicable law and identity verification, you may ask to access or correct personal data, withdraw consent where processing depends on consent, object to certain direct marketing, or request deletion. Some requests may be limited where information must be retained for security, legal, contractual, evidentiary, or dispute purposes.
For project data controlled by your company, contact the workspace owner or your employer first. You may also contact us at [LEGAL AND PRIVACY CONTACT EMAIL]. We may ask for information needed to verify your identity, workspace, and authority before acting.
12. Updates and contact
We may update this policy when our service, providers, or legal obligations change. We will post the revised effective date and provide reasonable notice of material changes.
For privacy questions, access or correction requests, withdrawal of consent, or data-deletion requests, contact [LEGAL AND PRIVACY CONTACT EMAIL]. Legal questions are governed together with our Terms and Conditions.
